{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:da23effc-8257-569b-af68-ef964babe6be",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jms",
      "version": "5.3.39-tuxcare.14",
      "purl": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3046bc0e-ed94-5afa-a706-c0572140fe64",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1da3bae7-d2d6-5772-87b2-5572ab1174dd",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.14 of org.springframework:spring-jms. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:105f9cfc-e69b-5f36-b995-c4570c371e5d",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8a67719-ab39-5b02-ba07-2a90a82cd34f",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed40fa52-4930-57a1-b707-56a81d6d7ca5",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c89be2d-6cc5-5895-af33-a1572f71c01d",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aa0e59e-3212-574d-95ba-9ebb5a83028f",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7be21e52-9f27-5b85-bfc2-26b598f0e16e",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-jms 5.3.39-tuxcare.14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96d38074-2df2-5e90-971f-12d2fc4ff1e2",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20576de2-81fc-5f7b-9109-f0241de1b5fa",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8a5edea-85ad-5896-8f5a-71e0fff62f9c",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9e17f13-6c38-5c2d-bc9e-5c3eea35d11d",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4445602f-0887-5acc-b304-ad92de865a1c",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd5c545e-159f-5310-a206-9cd7a1def21b",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:947f06f4-f20d-5db2-b207-b766d4f60fb2",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8a64b25-8608-54a5-be86-e4dc2e55bda9",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:017b389e-ff58-5d54-876b-1d7c327f0a6b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68ff9e84-20d4-5c02-9617-337b21938af6",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92a6d20f-d4b2-5267-a6a0-fad2a0cfa59e",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.14 of org.springframework:spring-jms. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19d180c7-9712-58d3-9f83-f976a4ca4882",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2b718a4-4237-5f0b-9401-af51e232f5f9",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0754b91d-a866-5d53-b260-78e249beb310",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d177282-7c45-528b-92d4-c01169568ab0",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:469b5683-df1d-5a5d-9572-e2a91356fa1f",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20bd77ff-09c2-5d03-aede-e9c177c5076a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e0175c9-75dc-551f-98fc-e92bed92ac27",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e4d5b49-f958-598f-9625-e60a3032d827",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fe5f4ba-6384-5abd-b051-e2135d00a46e",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18b8bd6b-f56e-52f1-ac16-9d61fcb46e65",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe892c6d-ddc1-5332-b72a-ef46f92505cd",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddd3b2ef-d9f5-5c05-9833-3426b64e2d98",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e49cca1-6aa4-5e5d-9b2f-b8d9e2b765fd",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fc17397-e735-57e0-a9f0-4ba4185467f2",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.14 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jms@5.3.39-tuxcare.14"
    }
  ]
}